Quick Summary
AllegedExecutive Summary
Prefeitura Municipal de Arcos, the municipal government of Arcos, Minas Gerais, Brazil, was listed on the dark web portal of the Emperador ransomware group on August 18, 2026. This listing follows a wave of credential harvesting that targeted the city’s email and privileged server infrastructure in the weeks preceding the extortion announcement. As a public institution, Prefeitura Municipal de Arcos likely possesses significant citizen data, making it a potentially attractive target for ransomware and extortion groups that focus on under-resourced public sector entities. Emperador has claimed two other victims in the 60 days prior to this incident: the City Government of Baguio and Albania’s Official National Teacher Training Portal. The targeting of these three distinct entities across Brazil, the Philippines, and Albania suggests Emperador prioritizes vulnerable targets over specific geographic regions. The group consistently targets the Government & Defense and Education sectors. Prefeitura Municipal de Arcos aligns with Emperador’s established pattern of targeting public institutions that may have fewer resources to defend against sophisticated cyberattacks, particularly those holding sensitive citizen data.
Technical Analysis
SOCRadar’s stealer-log telemetry identified 16 employee credentials associated with the domain arcos[.]mg[.]gov[.]br. These credentials provided access to various systems including mail infrastructure (mail[.]arcos[.]mg[.]gov[.]br), privileged server access endpoints (server[.]arcos[.]mg[.]gov[.]br on ports 6580 and 980), administrative portals, and internal application subdomains. A significant portion of these credentials, including admin-level and root-level accounts, were harvested on July 13, 2026, across multiple high-value endpoints. This concentration of harvested credentials on a single day is indicative of either a single compromised host or successful lateral movement within the network. The collected credentials show log dates spanning from July 1, 2026, to August 17, 2026. Notably, these credentials remained unrotated up to the day before the Emperador listing appeared on August 18, 2026. The exposure of these credentials across critical infrastructure like mail systems and privileged servers suggests a potential pathway for attackers to gain unauthorized access, exfiltrate data, and deploy ransomware. Audit access logs for all identified endpoints from July 1, 2026, onward. Treat every exposed account as compromised. Mail infrastructure and the privileged server endpoints are the highest-priority targets for forensic review.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.